Cybersecurity

How to Write a Business Password Policy

Create a modern password policy based on length, uniqueness, password managers, MFA, and breached-password screening.

Reviewed October 11, 2026 3 minute read Reviewed by Meta IT Pro
How to Write a Business Password Policy — Cybersecurity illustration from Meta IT Pro
Part of the Cybersecurity Learning Center

A modern password policy favors long, unique passwords, password managers, and multifactor authentication over complex character rules and frequent forced changes.

Key takeaways

What to know before you act

  • Current NIST guidance emphasizes length and screening against compromised passwords instead of complex composition rules.
  • Routine forced password changes are discouraged unless there is evidence of compromise.
  • A policy is only effective when paired with a password manager and multifactor authentication.

Why it matters

What business leaders should understand

Outdated policies can push employees toward predictable patterns and reused passwords. A clear, current policy improves security while reducing frustration and help-desk resets.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

What a modern password policy should include

Keep the policy short and practical. Employees should be able to follow it without memorizing a page of rules.

  • Minimum length: require a meaningful minimum and allow long passphrases.
  • Screening: block passwords found in breach lists, dictionary words, and obvious patterns such as the company name.
  • Uniqueness: never reuse a work password elsewhere.
  • Storage: use the approved business password manager; no spreadsheets, sticky notes, or browser storage.
  • MFA: required for email, remote access, financial systems, and administrators.
  • Changes: required after suspected compromise, not on an arbitrary schedule.
  • Shared accounts: avoided where possible; otherwise stored in a controlled vault with an owner.

Rolling it out without frustration

Explain why the rules changed. Many employees have been taught that frequent changes and symbols make passwords strong; replacing that habit requires a short explanation and good tools.

Configure technical controls to match the written policy—for example, password length and banned-password lists in Microsoft Entra ID or Google Workspace—so the system enforces what the document says. Review the policy annually and after significant incidents.

Practical action plan

Steps your business can take

01

Set a meaningful minimum length and allow long passphrases.

02

Screen new passwords against known breached and common passwords.

03

Provide a business password manager and require MFA for key systems.

04

Require changes when compromise is suspected rather than on a fixed schedule.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • Passwords must change every 30 or 60 days with no other controls
  • Employees store passwords in spreadsheets or browsers
  • The policy does not mention MFA or shared accounts

Frequently asked questions

Common questions, answered.

What should a modern password policy require?

A meaningful minimum length, screening against breached passwords, unique passwords, a password manager, and MFA.

Should passwords expire every 90 days?

NIST discourages routine forced changes; require changes when compromise is suspected.

Do we still need complexity rules?

Current guidance favors length and breached-password screening over composition rules.

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.